AWS Security ChangesHomeSearch

AWS mgn: Update manual MGN connector IAM policy examples and trust condition

Service: mgn · 2026-09-27 · Documentation medium

File: mgn/latest/ug/create-permissions-manually.md · Type: iam

Summary

Replaces placeholder tokens with concrete example values and changes the trust relationship condition operator from StringLike to ArnLike for aws:SourceArn.

Security assessment

Same IAM trust policy correction as the console doc: aws:SourceArn now uses ArnLike, the correct operator for ARN matching, improving the cross-account role assumption condition.

Evidence

+                    "ArnLike": {

Diff

diff --git a/mgn/latest/ug/create-permissions-manually.md b/mgn/latest/ug/create-permissions-manually.md
index 39dea5f80..e6b6375fb 100644
--- a//mgn/latest/ug/create-permissions-manually.md
+++ b//mgn/latest/ug/create-permissions-manually.md
@@ -25 +25 @@ To create the role:
-  1. After replacing **ACCOUNT-ID** with your account number, and **AWS_REGION** with the connector region, create a policy from the following JSON:
+  1. In the following JSON, replace the example account ID `111122223333` with your account number, and the example Region `us-east-1` with the connector Region. Then, create a policy from the JSON:
@@ -32 +32 @@ To create the role:
-                "Resource": "arn:aws:mgn:AWS_REGION:ACCOUNT-ID:*",
+                "Resource": "arn:aws:mgn:us-east-1:111122223333:*",
@@ -37 +37 @@ To create the role:
-                "Resource": "arn:aws:mgn:AWS_REGION:ACCOUNT-ID:connector/*",
+                "Resource": "arn:aws:mgn:us-east-1:111122223333:connector/*",
@@ -47 +47 @@ To create the role:
-                "Resource": "arn:aws:iam::*:role/AWSApplicationMigrationConnectorSharingRole_ACCOUNT-ID",
+                "Resource": "arn:aws:iam::*:role/AWSApplicationMigrationConnectorSharingRole_111122223333",
@@ -57 +57 @@ To create the role:
-                "Resource": "arn:aws:secretsmanager:AWS_REGION:ACCOUNT-ID:secret:*",
+                "Resource": "arn:aws:secretsmanager:us-east-1:111122223333:secret:*",
@@ -63,2 +63,2 @@ To create the role:
-                    "arn:aws:s3:::aws-application-migration-service-AWS_REGION/latest/source-automation-client/linux/ssaf-client/ssaf_client",
-                    "arn:aws:s3:::amazon-ssm-AWS_REGION/*"
+                    "arn:aws:s3:::aws-application-migration-service-us-east-1/latest/source-automation-client/linux/ssaf-client/ssaf_client",
+                    "arn:aws:s3:::amazon-ssm-us-east-1/*"
@@ -155 +155 @@ To create the role:
-                        "aws:SourceAccount": "management-account-id"
+                        "aws:SourceAccount": "111122223333"
@@ -157,2 +157,2 @@ To create the role:
-                    "StringLike": {
-                        "aws:SourceArn": "arn:aws:mgn:*:management-account-id:*"
+                    "ArnLike": {
+                        "aws:SourceArn": "arn:aws:mgn:*:111122223333:*"
@@ -165 +165 @@ To create the role:
-                    "AWS": "arn:aws:iam::management-account-id:role/AWSApplicationMigrationConnectorManagementRole"
+                    "AWS": "arn:aws:iam::111122223333:role/AWSApplicationMigrationConnectorManagementRole"